evasion-js-string-concat-capability
SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL
This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing.
Corpus ID: LF-CH-EVAS-0009
Purpose
Dormant JavaScript child-process strings are reconstructed at runtime.
Direct expected Layerfault rules
- None; this repository is a control/comparison input.
Candidate rules
These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them.
LF-JS-SEMANTIC-PROCESS
Negative-control rules
These should remain silent for this corpus item.
- None
Safety
The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output,
and synthetic model behavior only. It is intended for static scanning and isolated security testing.
Challenge classification
- Severity: high
- Difficulty: adversarial
- Expected admission decision: BLOCK
- Control type: positive
- Attack surface: package-evasion
- Techniques: javascript-string-concat
- Transformations: string-splitting
Ground-truth oracle IDs
LF-ORACLE-PACKAGE-OBFUSCATED-CAPABILITY
These oracle IDs describe synthetic ground truth. They do not claim that a matching Layerfault detector already exists. A challenge may intentionally expose a scanner blind spot and remain unmapped until the detector is implemented.
- Downloads last month
- 8